CVE-2013-2067

Apache Tomcat 6.0.21-6.0.36 and 7.x < 7.0.33 - Session Fixation via Form Authentication

Title source: llm
STIX 2.1

Description

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

References (23)

Core 23
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1437.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0839.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0964.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-7.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0833.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/59799
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1841-1
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0834.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64758
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-05/0041.html

Scores

EPSS 0.0715
EPSS Percentile 93.5%

Details

CWE
CWE-287
Status published
Products (41)
apache/tomcat 6.0.21
apache/tomcat 6.0.24
apache/tomcat 6.0.26
apache/tomcat 6.0.27
apache/tomcat 6.0.28
apache/tomcat 6.0.29
apache/tomcat 6.0.30
apache/tomcat 6.0.31
apache/tomcat 6.0.32
apache/tomcat 6.0.33
... and 31 more
Published Jun 01, 2013
Tracked Since Feb 18, 2026